Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    AI models need more data about biology, and OpenAI is paying to create it

    September 16, 2026

    Single CAR T Injection Eases Multiple Sclerosis Symptoms in Small Trial

    September 15, 2026

    AI ‘Actor’ Tilly Norwood Told Me That ‘All Lives Matter’

    September 15, 2026
    Facebook X (Twitter) Instagram
    Trending
    • AI models need more data about biology, and OpenAI is paying to create it
    • Single CAR T Injection Eases Multiple Sclerosis Symptoms in Small Trial
    • AI ‘Actor’ Tilly Norwood Told Me That ‘All Lives Matter’
    • Roundtables: Could AI really kill us all?
    • How Elon Musk and Tesla Forged a New EV Path
    • The Download: AI doomers, whistleblowing agents, and de-aged livers
    • Inside the Inference Hardware Revolution Of 2026
    • What must happen for AI’s trillion-dollar gamble to pay off
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»Ghost Accounts Abuse GitHub API in Mass Recon Campaign
    Cybersecurity

    Ghost Accounts Abuse GitHub API in Mass Recon Campaign

    kirklandc008@gmail.comBy kirklandc008@gmail.comJuly 11, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Software security
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Threat actors are abusing the GitHub API to systematically enumerate organizations, repositories, and user accounts, Datadog reports.

    Spanning multiple overlapping campaigns, the activity has been ongoing for several months, relying on ghost accounts that were registered two to five years ago but left dormant.

    The activity, Datadog says, involves automated scanners, the abuse of leaked credentials, and coordinated networks of dormant accounts.

    While the observed GitHub API requests are targeting publicly available data, blending with normal traffic, the continuous activity that in some cases escalated to the attackers cloning discovered repositories raises concern.

    “A large share of GitHub’s API surface is reachable without authentication. Listing an organization’s public repositories, walking a user’s followers and following lists, enumerating gists, starred repos, and org memberships, and running GraphQL queries against public objects all return data,” Datadog explains.

    Requests against these public paths generate HTTP 200 responses and no authentication failure signals. Through normal API traffic, an operator can use this to map an organization, its members, and the projects they access.

    Advertisement. Scroll to continue reading.

    Since at least October 2025, over 50 ghost accounts have been used to send API traffic as part of the enumeration, usually in bursts of 1 to 3 weeks, across multiple organizations.

    The accounts have been using user agents named to sound like data exfiltration, analytics, or dashboard tools. Most of the requests have been targeting GraphQL, while others have been aimed at REST routes.

    “On its own, this enumeration rarely produces meaningful access inside an organization, rather it’s accomplishing reconnaissance,” Datadog notes.

    One campaign was also seen using inadvertently exposed tokens from legitimate GitHub users, targeting private repository commit paths from dozens of legitimate accounts over a window of several minutes.

    In rare cases, the attackers moved beyond reconnaissance and successfully exfiltrated data from the targeted organizations, Datadog says.

    To detect this type of malicious activity, the cybersecurity firm notes, defenders should look for data exfiltration from private repositories, and should check logs for anomalous user agent behavior and for user agent naming and versioning in actions that reach private repositories.

    “User agents, event activity, and actor names are vital clues to unauthorized activity in your environment. It’s important to know what normal looks like in your environment. We suggest enabling GitHub audit log streaming, baselining your user agents, proactively threat hunting, and developing detections unique to your GitHub organization,” Datadog notes.

    Related: Network of 200 GitHub Repositories Used for Malware Infection

    Related: China, India-Linked Hackers Both Targeted Same Pakistani Police Force

    Related: Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers

    Related: Chinese Framework Powers 200,000 Scam Sites

    abuse accounts API Campaign Ghost GitHub Mass Recon
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    San Francisco Orders Meta to Stop ‘Allowing’ AI Child Abuse Ads

    September 10, 2026

    Meta Ran Ads That Contained AI-Generated Child Sexual Abuse Imagery

    August 6, 2026

    Ransomware in 2026: More groups, more victims, no slowdown

    July 26, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    The best VPN routers of 2026: Expert tested and reviewed

    June 14, 20263 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • AI models need more data about biology, and OpenAI is paying to create it
    • Single CAR T Injection Eases Multiple Sclerosis Symptoms in Small Trial
    • AI ‘Actor’ Tilly Norwood Told Me That ‘All Lives Matter’
    • Roundtables: Could AI really kill us all?
    • How Elon Musk and Tesla Forged a New EV Path

    AI models need more data about biology, and OpenAI is paying to create it

    September 16, 2026

    Single CAR T Injection Eases Multiple Sclerosis Symptoms in Small Trial

    September 15, 2026

    AI ‘Actor’ Tilly Norwood Told Me That ‘All Lives Matter’

    September 15, 2026

    Roundtables: Could AI really kill us all?

    September 15, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.